Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ permissions:

jobs:
cargo-deny:
name: cargo-deny (advisories, bans, sources)
name: cargo-deny (advisories, bans, sources, licenses)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
Expand All @@ -25,5 +25,5 @@ jobs:
# Run cargo-deny on the runner directly (the musl container action conflicts with the repo's rust-toolchain file).
- name: Install cargo-deny
uses: taiki-e/install-action@cargo-deny
- name: Check advisories, bans, sources
run: cargo deny check advisories bans sources
- name: Check advisories, bans, sources, licenses
run: cargo deny check advisories bans sources licenses
1 change: 1 addition & 0 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -117,6 +117,7 @@ jobs:
- "--no-default-features --features=time"
- "--no-default-features --features=rustls"
- "--no-default-features --features=vendored-openssl"
- "--no-default-features --features=rustls,chrono,time,tds73,rust_decimal,bigdecimal"

env:
TIBERIUS_TEST_CONNECTION_STRING: "server=tcp:localhost,1433;user=SA;password=<YourStrong@Passw0rd>;TrustServerCertificate=true"
Expand Down
22 changes: 22 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,27 @@
# Changes

## Version 0.13.0

- BREAKING: the connection-string `encrypt` default is now `Required` (was
`Off`) when a TLS backend is enabled, matching modern ADO.NET; without a TLS
backend it remains `NotSupported`.
- BREAKING: removed the `sql-browser-async-std` feature and the async-std SQL
Browser integration.
- feat: `Command`/RPC API for parameterized stored-procedure calls, plus a
`#[derive(TableValueRow)]` macro (in `tiberius-macros`) for table-valued
parameters.
- feat: `sspi-rs` feature for Windows-style SSPI/NTLM authentication on Unix via
the pure-Rust `sspi` crate (no Kerberos required).
- feat: `serde` feature adding `Serialize`/`Deserialize` impls for query result
types (`Row`, `Column`, `ColumnData`, `Numeric`, and the time/xml types).
- feat: client-certificate authentication, including PEM/DER key files
(`Config::client_certificate`) and PKCS#12 bundles
(`Config::client_certificate_pkcs12`).
- chore: upgraded the rustls stack to 0.23 (tokio-rustls 0.26) and resolved the
associated advisories.
- fix: numerous decode-path hardening fixes (protocol errors instead of panics
or stream desyncs on hostile server input across the codec/token modules).

## Version 0.12.3
- feat: improve column type accuracy (#347)
- fix: encoding of zero-length values for large varlen columns (#315)
Expand Down
1 change: 1 addition & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ authors = [
description = "A TDS (MSSQL) driver"
documentation = "https://docs.rs/tiberius/"
edition = "2021"
rust-version = "1.88"
keywords = ["tds", "mssql", "sql"]
license = "MIT/Apache-2.0"
name = "tiberius"
Expand Down
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,10 +44,12 @@ A native Microsoft SQL Server (TDS) client for Rust.
| `time` | Read and write date and time values using `time` crate types. | `disabled` |
| `rust_decimal` | Read and write `numeric`/`decimal` values using `rust_decimal`'s `Decimal`. | `disabled` |
| `bigdecimal` | Read and write `numeric`/`decimal` values using `bigdecimal`'s `BigDecimal`. | `disabled` |
| `sql-browser-async-std` | SQL Browser implementation for the `TcpStream` of async-std. | `disabled` |
| `sql-browser-tokio` | SQL Browser implementation for the `TcpStream` of Tokio. | `disabled` |
| `sql-browser-smol` | SQL Browser implementation for the `TcpStream` of smol. | `disabled` |
| `integrated-auth-gssapi` | Support for using Integrated Auth via GSSAPI | `disabled` |
| `winauth` | Windows-only SSPI/NTLM integrated authentication (`AuthMethod::Windows`). | `enabled` |
| `sspi-rs` | Windows-style SSPI/NTLM authentication on Unix via the pure-Rust `sspi` crate (no Kerberos required). | `disabled` |
| `serde` | `serde` `Serialize`/`Deserialize` impls for query result types (`Row`, `Column`, `ColumnData`, `Numeric`, etc.). | `disabled` |

### Supported protocols

Expand Down
20 changes: 20 additions & 0 deletions deny.toml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,26 @@ ignore = [
{ id = "RUSTSEC-2024-0436", reason = "paste: dev/test only (tests/bulk.rs + azure_identity example); not shipped" },
]

[licenses]
# Allow-list for the current dependency graph (verified locally with
# `cargo deny check licenses`). Every crate resolves to at least one of these
# via its SPDX expression; add new entries here rather than loosening the policy.
allow = [
"MIT",
"MIT-0",
"Apache-2.0",
"Apache-2.0 WITH LLVM-exception",
"BSD-1-Clause",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"CC0-1.0",
"Unicode-3.0",
"Unlicense",
]
# Confidence threshold for detecting a license from its text (0.0 - 1.0).
confidence-threshold = 0.8

[bans]
multiple-versions = "warn"
wildcards = "allow"
Expand Down
2 changes: 1 addition & 1 deletion examples/aad-auth.rs
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ async fn main() -> anyhow::Result<()> {
let server = env::var("SERVER").expect("Missing SERVER environment variable.");
config.host(server);
config.port(1433);
config.authentication(AuthMethod::AADToken(token.token.secret().to_owned()));
config.authentication(AuthMethod::aad_token(token.token.secret()));
config.trust_cert();

let tcp = TcpStream::connect(config.get_addr()).await?;
Expand Down
Loading